Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-2522
HistoryJul 25, 2022 - 12:00 a.m.

CVE-2022-2522

2022-07-2500:00:00
ubuntu.com
ubuntu.com
23
github repository
vim/vim
buffer overflow
cve-2022-2522
bug bounty
conversation
bug fix
side effect
commit
backporting
unix

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

47.0%

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.

Bugs

Notes

Author Note
rodrigo-zaiden there is a conversation in the bugbounty link that says that the correct fix is b9e71736 and not 5fa9f23a as previously stated. this issue is a side effect of CVE-2022-2343, that is, it was inserted with commit caea6644 (version 9.0.0045) that was added to fix CVE-2022-2343.
eslerm backporting requires at least f9706e9 and c593bec
OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchvim< 2:8.2.3995-1ubuntu2.11UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

47.0%